WelcomeProducts & ServicesSecurity ResponseSupportSolutions & IndustriesLicensingTrainingStore
Enterprise
Symantec.com > Enterprise > Support > Knowledge Base


Clients stop communicating with Symantec Endpoint Protection Manager (SEPM) with HTTP 401 error in Sylink log and HTTP 401.1 error in IIS log

Question/Issue:
Clients stop communicating with SEPM after replacing the sylink or after re-deploying the client install package. Sylink monitor logs show HTTP 401 errors, and IIS logs show 401.1 errors.

Symptoms:
Clients loses the green dot and stops communicating with the manager. Dropping the sylink or re-deploying the client package does not restore communications.

The following entries are seen in the Sylink logs:

The following entries are seen in the IIS logs:

Cause:
The issue can occur if anonymous access is configured in IIS and the anonymous access account password is not same as than the actual information stored in local user database or in Active Directory.


Solution:

If the SEPM is on a Domain:

  1. Open Active directory Users or Computers and search for the IUSR account
  2. Right click on the IUSR account and select Reset Password
  3. After resetting the password put the same password for the IUSR in IIS
  4. Restart the IISAdmin and SEPM Service

If the SEPM is in a Workgroup
  1. Right click My Computer and choose Manage
  2. Expand Local Users and Groups
  3. Click on users and find the IUSR account
  4. Once found, right click on the user and click on reset password



References:
http://support.microsoft.com/kb/907273/


Document ID: 2008032702341648
Last Modified: 02/26/2010
Date Created: 03/26/2008
Operating System(s): Windows Server 2003 Web/Standard/Enterprise/Datacenter Edition
Product(s): Endpoint Protection 11
Release(s): Endpoint Protection 11.0.1


Site Index · Legal Notices · Privacy Policy · · Contact Us · Global Sites · License Agreements
©1995 - 2010 Symantec Corporation